Skip to content
Snippets Groups Projects
Verified Commit 6cd1b35b authored by Sheogorath's avatar Sheogorath :european_castle:
Browse files

feat(findmydevice): Move to new kustomize-optimised config

parent 1b811254
No related branches found
No related tags found
No related merge requests found
apiVersion: kustomize.config.k8s.io/v1beta1 apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
namespace: findmydevice namespace: findmydevice
commonLabels:
app.kubernetes.io/name: findmydevice
buildMetadata:
- originAnnotations
resources: resources:
- namespace.yaml - namespace.yaml
- release.yaml - release.yaml
- ../../../shared/networkpolicies/allow-from-same-namespace.yaml - ../../../shared/networkpolicies/allow-from-same-namespace.yaml
- ../../../shared/networkpolicies/allow-from-ingress.yaml - ../../../shared/networkpolicies/allow-from-ingress.yaml
- ../../../shared/networkpolicies/allow-from-monitoring.yaml - ../../../shared/networkpolicies/allow-from-monitoring.yaml
patchesStrategicMerge:
- networkpolicy.yaml components:
- ../../../shared/components/flux-namespace-admin
- ../../../shared/components/namespace-baseline
...@@ -2,30 +2,3 @@ apiVersion: v1 ...@@ -2,30 +2,3 @@ apiVersion: v1
kind: Namespace kind: Namespace
metadata: metadata:
name: findmydevice name: findmydevice
labels:
pod-security.kubernetes.io/audit: restricted
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/audit-version: v1.26
pod-security.kubernetes.io/enforce-version: v1.23
pod-security.kubernetes.io/warn-version: v1.26
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: flux-reconciler
namespace: findmydevice
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: flux-reconciler
namespace: findmydevice
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: admin
subjects:
- kind: ServiceAccount
name: flux-reconciler
namespace: findmydevice
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-from-ingress
spec:
podSelector:
matchLabels:
app.kubernetes.io/name: findmydevice
---
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-from-monitoring
spec:
podSelector:
matchLabels:
app.kubernetes.io/name: findmydevice
...@@ -4,7 +4,6 @@ metadata: ...@@ -4,7 +4,6 @@ metadata:
name: findmydevice name: findmydevice
namespace: findmydevice namespace: findmydevice
spec: spec:
serviceAccountName: flux-reconciler
timeout: 15m timeout: 15m
releaseName: fmd releaseName: fmd
chart: chart:
......
apiVersion: kustomize.config.k8s.io/v1beta1 apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
namespace: findmydevice namespace: findmydevice
commonLabels:
app.kubernetes.io/name: findmydevice
app.kubernetes.io/instance: findmydevice
resources: resources:
- ../../base/findmydevice - ../../base/findmydevice
- certificate.yaml - certificate.yaml
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment